Lenovo HTTPS Boot

Intel Hardware Shield

Intel Hardware Shield helps minimize the risk of malicious code injection. This new firmware feature, available in the Intel® vPro™ platform, locks the BIOS when software is running to help prevent planted malware from gaining traction.

3M Filters

Absolute Software

Provides IT admins with a reliable two-way connection with all of their devices, so they can secure endpoints, assess risk, and respond appropriately to security incidents. Most importantly, they can apply remote security measures to protect each device and the data it contains.

Anti Bridge Switch

Asset Tagging Service

With Lenovo’s Standard and Enhanced Asset Tagging services, customers can have information-rich, tamper-resistant asset tags affixed to their PC and/or stored in the system’s BIOS before the PC is delivered to them. Asset tags can also be etched into the system lid, if etching is available in country.

BIOS Asset Information Area

BIOS Reading Room

A premium service that allows customers to visually inspect all Lenovo Think commerical products’ BIOS source code in a controlled physical environment. Nearly 2 MILLION lines of source code available for inspection*

C-TPAT Logistics

Lenovo logistics covers packaging, shipping, and delivery. Once the products are built and tested, they are packaged and prepared for shipping with tamper-evident materials so that any problems can be noticed immediately and in route, and the incident investigated. After packaging, Lenovo works with qualified logistics suppliers to safely deliver products to end customers. Protec- tion throughout the shipping process includes secure facilities, trucks and conveyances, and thoroughly-screened employees, visi- tors, and drivers. Shipments are tracked from the time they leave Lenovo buildings until they are received at a customer’s location.

Intel Boot Guard

ITC First Boot Service

Lenovo’s First Boot Services (FBS), shifts unattended first boot tasks (PC image set-up processes that must be completed before a technician or end-users can use the device) –into Lenovo manufacturing, increasing security and reducing time, resources, and cost necessary for IT admins to deploy PCs.

Kensington Lock

LVFS & WU Firmware Update

Lenovo provides not only driver and software updates, but also BIOS and system level firmware updates to the LVFS (Linux Vendor Firmware Service) and Windows Update. Ensures that IT admins can have a secure single source for all updates.

Packaging Security

Lenovo logistics covers packaging, shipping, and delivery. Once the products are built and tested, they are packaged and prepared for shipping with tamper-evident materials so that any problems can be noticed immediately and in route, and the incident inves- tigated. After packaging, Lenovo works with qualified logistics suppliers to safely deliver products to end customers. Protection throughout the shipping process includes secure facilities, trucks and conveyances, and thoroughly-screened employees, visitors, and drivers. Shipments are tracked from the time they leave Lenovo buildings until they are received at a customer’s location.

PSIRT & FIRST

Lenovo’s Product Security Incident Response Team (PSIRT) welcomes information about potential security vulnerabilities from security researchers, academics, and others in the wider security community. The PSIRT will investigate the issue, develop or source fixes, and then provide these fixes to Lenovo customers as quickly as possible.

Smart USB Protection

Spare Parts Handling

Lenovo Service Providers confirm that they track the disposal of products and parts. The Service Provider is solely responsible for all actions of their subcontractors have to ensure their own as well as their subcontractor compliance with environmental and security compliance guidelines. Lenovo Service Providers are required to provide full audit documentation to Lenovo.

Tamper Switch

The Lenovo Tamper Switch is present to prevent and/or notify IT admins of unauthorized access into a system. If the tamper switch is activated and triggered, then connection of the correct AC adapter and supervisor password is required.

ThinkShutter

ThinkShutter is a simple and secure mechanical cover that covers the camera on ThinkPad laptops. Solves a problem previously addressed by unsightly and unreliable sticky-notes with an easy to use and truly secure design. (Also available on some ThinkCentre all-in-one desktops).

Transparent Supply Chain

Transparent Supply Chain helps assure resellers and end-customers that their products come with a level of accountability and traceability unprecedented in the industry. The end result is a more secure supply chain for the industry.

Trusted Supplier Program

Lenovo’s Trusted Supplier Program plays a critical role in the development, manufacture, and delivery of our products. The supply chain begins with the management and control of a qualified supplier base, which provides qualified and secure components for use in development and manufacturing.

Data protection

Winmagic

WinMagic SecureDoc Enterprise is a flexible, scalable solution designed not only to protect data and ensure compliance, but more importantly to optimize operations and enable a unified encryption strategy across an enterprise.

Lenovo Secure Wipe

System Management Password

The System Management Password (SMP) is an additional password with significant, but lower authority than the Supervisor Password (SVP). This allows IT Administrators to give power users the SMP, which will enable them to make changes needed for their work, while IT Administrators still maintain complete control with the SVP.

Lenovo Data Protection by Carbonite

Absolute

Provides IT admins with a reliable two-way connection with all of their devices so they can secure endpoints, assess risk, and respond appropriately to security incidents. Most importantly, they can apply remote security measures to protect each device and the data it contains

BitLocker

BitLocker Drive Encryption is a data protection feature that integrates with the operating system and addresses the threats of data theft or exposure from lost, stolen, or inappropriately decommissioned computers.

Full Drive Encryption

HDD Password

ThinkPad/ThinkCentre/ThinkStation BIOSes all have the ability to set a secure HDD password that 1) locks the read/write ability of drives and 2) protects access to the encryption key on self encrypting drives

ThinkPad Privacy Guard

Trusted Service

Trusted service refers to the process Lenovo uses for ensuring that both Lenovo and its service providers handle all customer systems, equipment, and data securely during any repair or service, as well as during asset disposal

Identity protection

Intel Authenticate Multifactor

With Intel® Authenticate, users can log in fast without costly password resets, and IT teams can count on user identities and policies protected in a deep layer of silicon-based protection. PIN, biometrics, keys, tokens and associated certificates are captured, encrypted, matched, and stored in the hardware, out of sight and reach from typical attack methods.

FIDO

FIDO is an industry alliance providing open and scalable standards that enable simpler and more secure user authentication experiences across many websites and mobile services. Lenovo partner GO-Trust offers the ability to implement FIDO in the customer’s environment (AD, SSO, etc)

Mobile Iron

Lenovo Wi-Fi Security

A secure Wi-Fi access point solution (integrated into Lenovo Vantage) which uses behavioral rules and defined lists to notify users when connecting untrusted public networks by warning them of suspicious access point behavior.

Intel Software Guard Extensions

Lenovo Security Console

An enterprise-ready (rules definable by the customer) secure Wifi access point solution which uses behavioral rules and defined lists to notify users when connecting untrusted public networks by warning them of suspicious access point behavior.

Working together to fortify your business

ThinkShield brings world-class security providers together arm-in-arm to defend your company from security threats. Outfitting your business with modern Think devices, complete with the Intel® vPro™ platform and Windows 10 Pro, gives you the foundation for a secure business.

Security that's more usable for both admins and end-users

ThinkShield locks down your data without slowing down your team, offering automated and intelligent solutions that make your IT team more capable as defenders and growers of your business while staying out of the end-user's way.

IT RESOURCE TOOLKIT

We're here to help.

Find fresh perspectives and useful content to help elevate the importance of end-to-end security within your organization.